CVE-2026-1499 is a critical vulnerability (CVSS 3.1 base score 9.8) affecting the WP Duplicate WordPress plugin in all versions up to and including 1.1.8. The flaw is a missing authorization (capability) check on the process_add_site() AJAX action combined with a path traversal issue in the file upload functionality. An authenticated low-privileged user (subscriber-level) can set an internal option (prod_key_random_id) that enables an unauthenticated attacker to bypass authentication checks and invoke handle_upload_single_big_file() to write arbitrary files to the server. Successful exploitation can lead to remote code execution, full site compromise, deployment of web shells, data theft, and lateral movement within hosting environments.
References:

